PT-2024-7922 · Siemens · Sinema Remote Connect Server
Published
2024-07-09
·
Updated
2024-09-09
·
CVE-2024-39869
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:L/Au:S/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
SINEMA Remote Connect Server versions prior to V3.2 SP1
Description
The issue is related to insufficient checking of unusual or exceptional states in the web interface of the SINEMA Remote Connect Server. This can be exploited by a remote attacker to cause a denial-of-service situation. An authenticated attacker could upload crafted certificates, leading to a permanent denial-of-service situation. The only way to recover from such an attack is to manually remove the offending certificate.
Recommendations
For versions prior to V3.2 SP1, update to version V3.2 SP1 or later to resolve the issue. As a temporary workaround, consider restricting access to the certificate upload feature to minimize the risk of exploitation. Additionally, regularly monitor the system for any suspicious activity and be prepared to manually remove any offending certificates in case of an attack.
Fix
Improper Check for Exceptional Conditions
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sinema Remote Connect Server